Go to Home Page

Nokia Training


NSA: High Availability


 

Course Description
This one-day instructor-led course covers theory and practice of High Availability in a complete Check Point Nokia IPSO security system. The course is designed to be hands-on, and students will implement in the course of their lab exercises a security system with minimal – known and quantified – single points of failure.

 

Who Should Take This Course?
Technical persons tasked with the design, installation, and operation of Nokia security solutions with high uptime targets or where systems cannot be easily taken down for scheduled maintenance and upgrade should attend this course. This would include operation of any system where pairing IPSO systems in a cluster or a resilient pair mitigates a single point of failure.

 

Course Fee:$995

 

Course Prerequisites

Persons attending this course must have attended NSA: Foundation or they should have passed NSA certification.

 

Course Objectives
After completion of this course, participants will be able to:

  • Understand the theory of resilient design
  • Understand the IPSO alternatives of clustering and VRRP (virtual router resilience)
  • Understand how to combine these mechanisms with power provisions, appropriate switching technology and other related technologies to remove all single points of failure
  • Install an end-to-end solution

 

Topics Covered

  • Theory of resilient design
  • VRRP – simplified, and traditional mode MC
  • IPSO clustering
  • Check Point clustering, cluster objects, synchronization, sync configuration, and tuning by protocol and by delayed sync
  • Clustering integration with switches
  • Dual power, dual hard drive mirroring
  • Check Point multiple link/ISPs
  • Static route priorities and failover
  • Link aggregation

 

Course Outline

  • Introduction
  • General HA Theory
  • Hardware HA Theory
  • Reducing Single Points of Failure
  • Nokia HA Appliances
  • Lab Design
  • Initial Configuration
  • Simplified and Full VRRP
  • Integrating VRRP and Check Point VPN-1 NGX
  • Nokia IP Clustering
  • IP Clustering and VPN-1 Integration
  • Link Aggregation
  • ISP Link Redundancy
  • Static Route Priority Failover

     

    Note
    NSA:HA does not cover the use of dynamic routing as a resilience mechanism. Dynamic routing and routing over Check Point VPN are covered in NSA:Connectivity which is a companion course ot NSA:HA, and is highly recommended if you need to understand all of your options in implementing a highly available system.

  • Copyright 2007-2008 Forsythe Solutions Group, Inc. All Rights Reserved. Contents may not be reproduced in part or in whole, without written permission from Forsythe.